/api/v1/accounting/sage/start
auth: jwt (administrator)Begin a Sage OAuth2 authorisation flow for the caller's business. Generates PKCE + state, persists in OAuthStates, returns the Sage authorisation URL. Rate-limited (10/min open bucket).
handlers: SageAccountingAuthController.start
No parameters.
APIResponseDataObject<SageStartResponse>APIErrorAPIError/api/v1/accounting/sage/callback
auth: noneSage OAuth callback. Validates state, exchanges the code, upserts a single SageConnections row (Sage has one business per token — no tenant selection), then 302 redirects (desktop) or serves a 200 text/html bridge page (mobile) opening `vsms://auth/sage/{success|failure}`.
handlers: SageAccountingAuthController.callback
| name | required | default | description |
|---|---|---|---|
code querystring | no | — | OAuth authorisation code returned by Sage. |
state querystring | no | — | PKCE state issued by `/start`. |
error querystring | no | — | Set by Sage on failure or user denial. |
redirecttext/html/api/v1/accounting/sage/status
auth: jwtSage connection summary — whether a Sage connection exists, the connected Sage business, and the current `autoFiscaliseInvoices` flag.
handlers: SageAccountingAuthController.status
No parameters.
APIResponseDataObject<SageStatusResponse>APIError/api/v1/accounting/sage/connection
auth: jwt (administrator)Soft-deactivate the Sage connection for the caller's business (`IsActive=0`). Rows are retained for history; the user may re-authorise via `/sage/start`. Fires `SAGE_DISCONNECTED` audit.
handlers: SageAccountingAuthController.disconnect
No parameters.
APIResponseDataObject<{ deactivatedCount: number }>